Missing Authentication for Critical Function (CWE-306)
This vulnerability in the Deep Sea Electronics DSE855 device allows an attacker to bypass authentication and access functionality in the web-based UI without credentials. The lack of authentication for critical functions allows an unauthenticated, network-adjacent attacker to create a denial-of-service condition on the system.
An attacker could leverage this vulnerability to disable the DSE855 device and disrupt its services, potentially causing a denial-of-service for connected systems and networks that rely on the device. The vulnerability has a CVSS v3 base score of 4.3, indicating a medium severity level. The attack vector is adjacent network, meaning the attacker needs to be on the same network segment as the vulnerable device. The attack complexity is low, requiring no user interaction and no privileges to exploit.
One proof-of-concept exploit is available on zerodayinitiative.com. There is no evidence of proof of exploitation at the moment.
As of the latest information provided (May 24, 2024), the vulnerability remains unpatched. The vendor has not responded with a patch within the allotted 120-day disclosure policy timeframe.
Given the nature of the vulnerability, the primary mitigation strategy is to restrict interaction with the application. Additional mitigation measures may include: 1. Implementing network segmentation to isolate the DSE855 devices. 2. Applying strict access controls to limit network-adjacent access to the devices. 3. Monitoring for any unauthorized access attempts or unusual activity on the DSE855 devices. 4. Disabling the web-based UI if it's not essential for operations. 5. Regularly checking for and applying any future security updates from Deep Sea Electronics.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD published the first details for CVE-2024-5952
Feedly found the first article mentioning CVE-2024-5952. See article
Feedly estimated the CVSS score as HIGH
This CVE started to trend in security discussions
EPSS Score was set to: 0.04% (Percentile: 9%)
This CVE stopped trending in security discussions
A CVSS base score of 4.3 has been assigned.
A CVSS base score of 6.5 has been assigned.
A CVSS base score of 6.5 has been assigned.